CVE-2022-39272
- EPSS 0.31%
- Veröffentlicht 22.10.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:55
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, ...
CVE-2022-24878
- EPSS 0.31%
- Veröffentlicht 06.05.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:18
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include a...
CVE-2022-24877
- EPSS 0.62%
- Veröffentlicht 06.05.2022 01:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:18
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem and possibly ...
CVE-2022-24817
- EPSS 0.38%
- Veröffentlicht 06.05.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:09
Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfi...
- EPSS 0.98%
- Veröffentlicht 12.11.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:53
kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled with Kustomize. Users that can create Kubernetes Secrets, Service Acc...